Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Lollms Web Ui HIGH 7.7
CVE-2024-4498

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest…

Patch available
Fix from $1,950 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4885 KEVEPSS 99%

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.Exp…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Unclassified MEDIUM 5.0
CVE-2024-32111

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.T…

Mitigation only
Fix from $1,600 2024-06-25
Unclassified CRITICAL 9.8
CVE-2024-34313

An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.

Mitigation only
Fix from $2,300 2024-06-24
Codechecker MEDIUM 6.5
CVE-2023-49793

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the serv…

Fix: 6.23.0+
Fix from $1,600 2024-06-24
Sharepoint Bulk File Download CRITICAL 9.8
CVE-2024-33879

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx i…

Mitigation only
Fix from $2,300 2024-06-24
Sharepoint Bulk File Download MEDIUM 5.3
CVE-2024-33881

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx i…

Mitigation only
Fix from $1,600 2024-06-24
Unclassified MEDIUM 5.4
CVE-2024-37825

An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated a…

Mitigation only
Fix from $1,600 2024-06-24
Salon Booking System CRITICAL 9.1
CVE-2024-37231

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File…

Fix: 10.0+
Fix from $2,300 2024-06-24
Consulting Elementor Widgets HIGH 8.8
CVE-2024-37092

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PH…

Fix: 1.3.1+
Fix from $1,950 2024-06-24
Consulting Elementor Widgets CRITICAL 9.8
CVE-2024-37089

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PH…

Fix: 1.3.1+
Fix from $2,300 2024-06-24
Opencart HIGH 7.2
CVE-2024-21518EPSS 14%

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sa…

Patch available
Fix from $1,950 2024-06-22
Unclassified CRITICAL 9.1
CVE-2012-6664EPSS 30%

Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remote attackers to read or write…

No fix yet
Fix from $2,300 2024-06-21
Word Balloon MEDIUM 6.5
CVE-2024-35781

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YAHMAN Word Balloon allows PHP Local File Inclusion.T…

Fix: after 4.21.1
Fix from $1,600 2024-06-21
Slideshow Se HIGH 8.8
CVE-2024-35778

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE PHP Local File Inclusion.This …

Fix: after 2.5.17
Fix from $1,950 2024-06-21
Adminerevo CRITICAL 9.8
CVE-2023-45197

The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. …

Fix: 4.8.3+
Fix from $2,300 2024-06-21
Shariff Wrapper CRITICAL 9.8
CVE-2024-4098

The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_shar…

Fix: 4.6.14+
Fix from $2,300 2024-06-20
Localai CRITICAL 9.1
CVE-2024-5182EPSS 26%

A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion…

Fix: 2.16.0+
Fix from $2,300 2024-06-20
Reposilite HIGH 7.5
CVE-2024-36117

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affect…

Fix: 3.5.12+
Fix from $1,950 2024-06-19
Reposilite CRITICAL 9.8
CVE-2024-36116

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite provides support …

Fix: 3.5.12+
Fix from $2,300 2024-06-19
Unclassified CRITICAL 10.0
CVE-2024-37902

DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived a…

Mitigation only
Fix from $2,300 2024-06-17
Unclassified HIGH 7.7
CVE-2024-38449

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticat…

Mitigation only
Fix from $1,950 2024-06-17
Unclassified MEDIUM 6.5
CVE-2024-36527

puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read s…

Mitigation only
Fix from $1,600 2024-06-17
Unclassified MEDIUM 6.5
CVE-2024-6044

Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbi…

Mitigation only
Fix from $1,600 2024-06-17
Cloudpanel HIGH 8.8
CVE-2024-24320

Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execut…

Fix: after 2.4.0
Fix from $1,950 2024-06-14
Unclassified HIGH 8.8
CVE-2024-2024

The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' …

Mitigation only
Fix from $1,950 2024-06-14
Unclassified HIGH 7.2
CVE-2024-27177

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability …

No fix yet
Fix from $1,950 2024-06-14
Unclassified HIGH 7.2
CVE-2024-27178

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can…

Mitigation only
Fix from $1,950 2024-06-14
Unclassified HIGH 7.2
CVE-2024-27176

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying session ID variable. This vulnerability can…

No fix yet
Fix from $1,950 2024-06-14
Unclassified CRITICAL 9.8
CVE-2024-27173

Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerab…

Mitigation only
Fix from $2,300 2024-06-14